Skip to main content

Plugin auth backend module cloudflare access provider: Backstage: Insufficient audience validation in the Cloudflare Access auth provider (CVE-2026-106457)

0
Medium
Published: 10/07/2026 (10/07/2026, 20:25:25 UTC)
Source: GCVE Database
Product: @backstage/plugin-auth-backend-module-cloudflare-access-provider

Description

The Cloudflare Access auth provider module for Backstage versions 0.1.0 up to but not including 0.5.0 does not verify that tokens presented for authentication were issued specifically for the Backstage application. This allows a user with a valid token for another Cloudflare Access application in the same Zero Trust team to authenticate to Backstage if the token reaches the auth endpoint without prior audience enforcement. The vulnerability depends on deployment configurations that allow direct or alternate access to the auth endpoint, bypassing normal Cloudflare Access protections. The impact depends on the permissions assigned to the authenticated identity. A fix is available in version 0.5.0 and later, which requires configuration changes to specify the correct audience.

CVSS v3.1

Score 6.8medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

npmghsa
@backstage/plugin-auth-backend-module-cloudflare-access-provider
Affected versions
>=0.1.0 <0.5.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 21:57:56 UTC

Technical Analysis

CVE-2026-106457 affects the @backstage/plugin-auth-backend-module-cloudflare-access-provider in versions >=0.1.0 <0.5.0. The module verifies token signature and team issuer but fails to validate the token's audience claim to ensure it was issued for the Backstage application. This flaw can allow an attacker holding a valid token for a different Cloudflare Access application within the same Zero Trust team to authenticate to Backstage if the token is presented directly to the auth endpoint without audience enforcement upstream. Typical Cloudflare Access deployments enforce audience checks before forwarding requests, so exploitation requires specific deployment topologies such as direct origin access or alternate proxy routes. The severity is medium with a CVSS 3.1 score of 6.8 (Network attack vector, High complexity, Low privileges required, No user interaction, High confidentiality and integrity impact, No availability impact). The issue is fixed in version 0.5.0, included in Backstage v1.55.0, which introduces a breaking configuration change requiring the audience to be explicitly set.

Potential Impact

An attacker with a valid Cloudflare Access token for another application in the same Zero Trust team may authenticate to Backstage without possessing a token specifically issued for it, potentially gaining unauthorized access depending on the permissions mapped to that identity. This can lead to unauthorized access to Backstage resources. However, exploitation requires specific deployment conditions where the auth endpoint is accessible without audience enforcement upstream. The confidentiality and integrity of Backstage data are at risk, but availability is not impacted.

Mitigation Recommendations

Upgrade the @backstage/plugin-auth-backend-module-cloudflare-access-provider package to version 0.5.0 or later. Before upgrading, configure the 'auth.providers.cfaccess.audience' setting to the correct Audience (AUD) tag for the Backstage application in Cloudflare Zero Trust. If immediate patching is not possible, restrict access to the Backstage auth endpoint to only the intended Cloudflare Access application, use a custom authenticator that validates the application audience, or disable the provider until the patch can be applied. These mitigations reduce the risk of unauthorized authentication via tokens issued for other applications.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-q333-f498-w2x7
Osv Schema Version
1.4.0
Aliases
["CVE-2026-106457"]
Ecosystems
["npm"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac6bfb72cdf04f656828c9f

Added to database: 10/07/2026, 21:55:03 UTC

Last enriched: 10/07/2026, 21:57:56 UTC

Last updated: 10/07/2026, 21:57:56 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses